Privacy Policy
This Privacy Policy explains how Haijahr Ltd ("Haijahr", "we", "us", or "our") collects, uses, stores, and protects personal data when you use Lysander — our practice management platform for counsellors, coaches, and therapy practitioners.
We are committed to protecting your personal data and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
1. Who We Are
The data controller for Lysander is:
61 Alexandra Road
Lowestoft, Suffolk
NR32 1PL
United Kingdom
Website: haijahr.com
Email: privacy@haijahr.com
Haijahr Ltd is registered with the Information Commissioner's Office (ICO) as a data controller. We are also the developer of Brefi, a separate product governed by its own privacy policy.
2. Data We Collect
2.1 Account and Registration Data
When you create a Lysander account we collect:
- Full name
- Email address
- Password (stored as a one-way cryptographic hash — never in plain text)
- Your professional role (Counsellor or Business Admin)
- Organisation name (if you create or join a practice organisation)
2.2 Patient Records
Lysander allows authorised counsellors to record information about their patients. This may include:
- Patient name, email address, date of birth, and phone number
- Session notes and clinical observations
- Task descriptions and assignment files
- Files uploaded by patients through their personal portal
Counsellors act as independent data controllers for their patient records. Haijahr acts as a data processor in respect of patient data and processes it solely on the instructions of the counsellor. You should ensure your patients are informed of this under your own professional privacy obligations.
2.3 Usage and Technical Data
We automatically collect certain technical data when you use Lysander, including:
- IP address and browser type
- Pages visited and features used
- Date and time of access
- Session identifiers stored in cookies
2.4 Communications
If you contact us by email or through our website, we retain a record of that correspondence including your contact details and the content of your message.
3. How We Use Your Data
We use your personal data for the following purposes:
- Providing the Lysander service — creating and managing your account, processing logins, and delivering the features you use
- Invitations and team management — sending invitation emails when a Business Admin invites a counsellor to their organisation
- Service communications — sending essential notices about your account, security alerts, or significant changes to the service
- Customer support — responding to your queries and resolving issues
- Security and fraud prevention — monitoring for abuse, unauthorised access, and maintaining the integrity of the platform
- Legal compliance — meeting our obligations under applicable law
- Service improvement — understanding how Lysander is used in aggregate to improve features and performance (using anonymised or pseudonymised data wherever possible)
We do not use your data for advertising, sell it to third parties, or use it to profile you for marketing purposes.
4. Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing and managing your account | Performance of a contract (Article 6(1)(b)) |
| Sending invitation emails | Legitimate interests (Article 6(1)(f)) — facilitating team collaboration you requested |
| Essential service communications | Legitimate interests (Article 6(1)(f)) — keeping you informed about your account |
| Security and fraud prevention | Legitimate interests (Article 6(1)(f)) — protecting users and the platform |
| Legal obligations | Legal obligation (Article 6(1)(c)) |
| Analytics cookies (if consented) | Consent (Article 6(1)(a)) |
| Processing patient records on behalf of counsellors | We act as a data processor; the counsellor is the data controller and must establish their own legal basis |
Where we rely on legitimate interests, we have balanced our interests against your rights and concluded that our processing does not override your fundamental rights and freedoms.
5. Data Sharing
We do not sell your personal data. We may share it with:
- Hosting and infrastructure providers — the servers that power Lysander. All providers are vetted and subject to data processing agreements.
- Email delivery services — used to send transactional emails such as invitation links. Only the recipient's email address and message content are shared.
- Professional advisers — lawyers, accountants, and auditors who are bound by professional confidentiality obligations.
- Law enforcement or regulators — where we are legally required to do so.
We require all third-party processors to handle your data securely and in compliance with UK GDPR. A current list of the sub-processors that may process patient data on our behalf — with their purpose and location — is published on our Sub-processors page.
6. International Transfers
We aim to store and process your data within the United Kingdom or the European Economic Area (EEA). If any transfer outside these areas is necessary — for example, by a cloud infrastructure provider — we ensure it is protected by appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs), in accordance with UK GDPR Chapter V.
7. Data Retention
We retain your personal data only for as long as necessary:
- Account data — retained for the duration of your account plus up to 3 years after account closure, to comply with legal and accounting obligations
- Patient records — retained as directed by the counsellor who controls them; counsellors are responsible for ensuring their own retention obligations are met
- Uploaded files — deleted when the associated record is deleted or when the account is closed
- Usage and technical logs — retained for up to 12 months for security purposes
- Support correspondence — retained for up to 3 years after the last contact
When data is no longer needed, it is securely deleted or anonymised.
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — you may request a copy of the personal data we hold about you
- Right to rectification — you may ask us to correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — you may ask us to delete your data where there is no overriding legal reason to retain it
- Right to restriction — you may ask us to restrict processing in certain circumstances
- Right to data portability — you may request your data in a structured, machine-readable format
- Right to object — you may object to processing based on legitimate interests
- Rights related to automated decision-making — Lysander does not make solely automated decisions that produce legal or similarly significant effects
- Right to withdraw consent — where processing is based on consent (e.g. analytics cookies), you may withdraw it at any time via the cookie preferences link in the footer
To exercise any of these rights, please contact us at privacy@haijahr.com. We will respond within one calendar month of receiving your request.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
ico.org.uk
10. Children's Privacy
Lysander is intended for use by professional practitioners and is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately at privacy@haijahr.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a prominent notice within Lysander before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.
Continued use of Lysander after the effective date constitutes acceptance of the revised policy.
12. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:
Haijahr Ltd
61 Alexandra Road, Lowestoft, Suffolk, NR32 1PL
Email: privacy@haijahr.com
Website: haijahr.com